# How to Reset the Password or SSH Key on a Linux based VM in Quake AI

Source: https://docs.quake.ai/docs/operate/troubleshooting/reset-password-ssh
Markdown: https://docs.quake.ai/docs/operate/troubleshooting/reset-password-ssh.md

---

# How to Reset the Password or SSH Key on a Linux based VM in Quake AI

Quake AI does not have special access to reset a user's password or SSH key. However, since a VM behaves like a normal server, standard processes can be used to perform a password reset if such a process exists for your operating system.  

This guide presents an example using **Ubuntu 24.04**, but the same process applies to most Linux distributions, and also for similar operating systems such as BSD-based derivatives.

---

## Before you begin



The Quake AI Ubuntu cloud image ships with `GRUB_TIMEOUT=0` and `GRUB_TIMEOUT_STYLE=hidden`, so a fresh boot has no GRUB interrupt window for ESC to land in.

If you still have working SSH or console password access, run these commands before you follow the GRUB recovery steps below:

```bash
sudo sed -i 's/^GRUB_TIMEOUT_STYLE=hidden/#&/' /etc/default/grub
sudo sed -i 's/^GRUB_TIMEOUT=0/GRUB_TIMEOUT=5/' /etc/default/grub
sudo update-grub
```

Then reboot and continue with step 3.

If you have already lost SSH and console password access, you cannot enable the interrupt window from inside the VM. Shut down the instance, detach the boot volume, attach it to a helper instance, mount the root filesystem, and reset credentials from there. See the [volume troubleshooting runbook](/docs/operate/runbooks/volume-troubleshooting) for detach and attach commands.



## Steps to reset a password or SSH key

### 1. Log in to the console
Open the **console** for your VM from the Quake AI dashboard.  

![Open Console Image](/images/docs/articles/troubleshooting/reset-password-ssh/image.png)

---

### 2. Prepare your console window
Resize your browser window so you can access the **"Send CtrlAltDel"** button in the top-right corner. 

Click inside the black console window so that your keystrokes register inside the VM instead of your local computer.  

![Console Window Image](/images/docs/articles/troubleshooting/reset-password-ssh/image-1.png)

---

### 3. Reboot and enter GRUB
Click **"Send CtrlAltDel"**. Immediately click inside the console window and **press ESC several times**.  

Because the VM reboots fast, act during the boot window. You should see the following GNU GRUB window. If instead the system continues to boot, allow the VM to boot fully, then repeat this step until you see the GRUB prompt after pressing the ESC key several times.

![GRUB Boot menu](/images/docs/articles/troubleshooting/reset-password-ssh/image-2.png)
---

### 4. Edit the boot entry
If you see the **GNU GRUB boot menu**, use the arrow keys to select the default boot entry (*Ubuntu* on the standard images).  

Press **`e`** to edit it.  

![GRUB Edit Entry](/images/docs/articles/troubleshooting/reset-password-ssh/image-3.png)

---

### 5. Add single-user mode
Scroll to the line that begins with `linux`.  

At the **end of the line**, add the word `single`  

![GRUB Edit Entry with the word single added](/images/docs/articles/troubleshooting/reset-password-ssh/image-4.png)

---

### 6. Boot into maintenance mode
Press **Ctrl+X** to boot with the modified entry.  

The system begins to boot, and you should eventually see:  

   ```bash
   Press Enter for Maintenance
   ```  

Press **Enter**, and you get a root shell prompt.  

![Maintenance mode shell](/images/docs/articles/troubleshooting/reset-password-ssh/image-5.png)

---

### 7. Reset a password
At the prompt, type:  

   ```bash
   passwd ubuntu
   ```  

This resets the password for the `ubuntu` user.  

You may also reset the password for `root` or any other user as needed.



On the Quake AI Ubuntu cloud image, the `ubuntu` and `root` accounts ship locked (`passwd -S` returns `L`), and `disable_root: true` in `/etc/cloud/cloud.cfg` blocks root SSH. Resetting `root`'s password does not by itself restore SSH access for `root`; you would also need to override `disable_root` and adjust sshd PermitRootLogin settings.



![Password reset](/images/docs/articles/troubleshooting/reset-password-ssh/image-6.png)

---

### 8. Exit maintenance mode
Type:  

   ```bash
   exit
   ```  

Your system should now continue booting to the normal login console.  

---

### 9. Access with password or SSH
- If you normally use **password-based access** (not recommended), you can now log in with the new password using your normal processes.  
- If you are using **SSH key-based access** (preferred), you will need to continue passed this step to also update your SSH key configuration.  

![Console Login](/images/docs/articles/troubleshooting/reset-password-ssh/image-7.png)

---

### 10. Reset SSH key access
SSH keys are stored in:  

   ```bash
   ~/.ssh/authorized_keys
   ```  

To update them:  

1. First, log in with your new password via SSH.  
2. Edit the `authorized_keys` file to add your new SSH key.  

⚠️ Since the web console does not allow cut-and-paste, this step is easiest to complete over an SSH session.

If your system is not configured to allow password login over SSH, you will need to **temporarily enable it**. For the Quake AI Ubuntu image, follow the instructions below. For other distributions the file location, etc. may be slightly different.:  

1. Edit: 

    ```bash
    /etc/ssh/sshd_config.d/60-cloudimg-settings.conf
    ```  
    Set:

    ```bash
    PasswordAuthentication yes
    ```

2. Restart SSH:  

    ```bash
    sudo systemctl restart ssh
    ```  

---

### 11. Revert temporary changes
After you confirm SSH key access is restored:  

1. Revert the SSH configuration change (`PasswordAuthentication no`).  
2. Optionally remove the password you set earlier by running:  

   ```bash
   sudo passwd -d ubuntu
   ```

---

## Troubleshooting

### GRUB does not appear
- Confirm you completed the GRUB timeout prerequisite in [Before you begin](#before-you-begin) if this is your first recovery attempt on the Quake AI Ubuntu cloud image.
- If the console does not capture your key presses, click inside the console window immediately after you select **Send CtrlAltDel**.

### System boots without maintenance prompt
- Double-check that you edited the correct `linux` line in GRUB.  
- Ensure the word **`single`** was added at the end of the line.  

### SSH keys get overwritten after reboot

The Quake AI Ubuntu cloud image's cloud-init configuration (`/etc/cloud/cloud.cfg`) does not overwrite `~/.ssh/authorized_keys` on reboot. If you observe this behavior on a non-Quake AI image, consult that image's cloud-init documentation (`/etc/cloud/cloud.cfg` and `/etc/cloud/cloud.cfg.d/`) and the upstream cloud-init `users` / `ssh_authorized_keys` reference. Do not edit `/etc/cloud/cloud.cfg` directly on a vendor-managed image; use a drop-in under `/etc/cloud/cloud.cfg.d/`.

### Cannot edit files in console
- The web console does not allow copy-paste. If you need to add long SSH keys, use **password login** temporarily, then update your key via an SSH session.  

---

## Summary
By following these steps, you can recover access to your Quake AI VM when password or SSH key access is lost. The process leverages standard Linux recovery workflows, meaning it works the same way as it would on a physical linux server.
